Extension WordPress
Vulnérabilités Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits
Cette page rassemble les failles publiées pour Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits
28 fiches
Master Addons For Elementor <= 3.1.0 – Authenticated (Author+) Stored Cross-Site Scripting via 'jtlma_custom_js' Page Setting (Custom JS Extension)
The Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'jtlma_custom_js' Page Setting (Custom JS Extension) in all versions up to, and including,…
*-3.1.0
3.1.1
05/06/2026
Freemius <= 2.10.1 – Reflected DOM-Based Cross-Site Scripting via url Parameter
Multiple plugins and/or themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the url parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
*-2.0.7.2
2.0.7.3
30/04/2026
Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits <= 2.1.3 – Authenticated (Author+) Stored Cross-Site Scripting
The Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.3 due to insufficient input sanitization and output…
*-2.1.3
2.1.4
16/03/2026
Master Addons For Elementor <= 2.1.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'ma_el_bh_table_btn_text'
The Master Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ma_el_bh_table_btn_text' parameter in versions up to, and including, 2.1.1 due to insufficient input sanitization and output escaping. This makes it possible for…
*-2.1.1
2.1.2
20/02/2026
Master Addons for Elementor <= 2.0.9.9.4 – Unauthenticated Insecure Direct Object Reference
The Master Addons For Elementor – White Label, Free Widgets, Hover Effects, Conditions, & Animations plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.9.9.4 due to missing validation on…
*-2.0.9.9.4
2.1.0
31/12/2025
Master Addons for Elementor <= 2.0.9.9.3 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Master Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.9.9.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…
*-2.0.9.9.3
2.1.0
05/12/2025
Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations <= 2.0.8.6 – Authenticated (Contributor+) Stored Cross-Site Scripting via fancyBox
The Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 2.0.8.6 due to…
*-2.0.9.0
2.0.9.1
11/08/2025
Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations <= 2.0.8.2 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom JS extension in all versions up to, and including, 2.0.8.2…
*-2.0.8.2
2.0.8.3
15/07/2025
Master Addons <= 2.0.7.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets
The Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 2.0.7.2 due to…
*-2.0.7.2
2.0.7.3
03/03/2025
Master Addons <= 2.0.7.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter
The Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 2.0.7.1 due…
*-2.0.7.1
2.0.7.2
03/03/2025
Master Addons — Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor <= 2.0.6.7 – Authenticated (Contributor+) Stored Cross-Site Scripting via Tooltip Module
The Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Tooltip module in all versions up to, and including, 2.0.6.7…
*-2.0.6.7
2.0.6.8
06/01/2025
Master Addons for Elementor <= 2.0.9.9.4 – Authenticated (Author+) Stored Cross-Site Scripting
The Master Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.9.9.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level…
*-2.0.9.9.4
2.1.0
11/11/2024
Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor <= 2.0.6.4 – Authenticated (Contributor+) Stored Cross-Site Scripting via data-jltma-wrapper-link Element
The Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-jltma-wrapper-link element in all versions up to, and including 2.0.6.4 due to insufficient input…
*-2.0.6.4
2.0.6.5
09/09/2024
Master Addons for Elementor <= 2.0.6.2 – Authenticated (Author+) Stored Cross-Site Scripting
The Master Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level…
*-2.0.6.2
2.0.6.3
11/07/2024
Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor <= 2.0.6.1 – Missing Authorization to MA Template Creation or Modification
The Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ma-template' REST API route in all versions…
*-2.0.6.1
2.0.6.2
06/06/2024
Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor <= 2.0.6.1 – Missing Authorization to Unauthenticated Stored Cross-Site Scripting via Navigation Menu Widget
The Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Navigation Menu widget of the plugin's Mega Menu extension in all versions up to,…
*-2.0.6.1
2.0.6.2
06/06/2024
Master Addons for Elementor <= 2.0.5.4.1 – Missing Authorization via get_jltma_save_menuitem_settings()
The Master Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the get_jltma_save_menuitem_settings function in versions up to, and including, 2.0.5.4.1. This makes it possible for unauthenticated…
*-2.0.5.4.1
2.0.5.6
03/06/2024
Master Addons for Elementor <= 2.0.6.0 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the title_html_tag attribute in all versions up to, and including, 2.0.6.0 due to insufficient input…
*-2.0.6.0
2.0.6.1
16/05/2024
Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor <= 2.0.6.0 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 2.0.6.0 due to insufficient input sanitization and…
*-2.0.6.0
2.0.6.1
15/05/2024
Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor <= 2.0.5.9 – Contributor+ Stored Cross-Site Scripting
The Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in versions up to, and including, 2.0.5.9 due to insufficient input sanitization…
*-2.0.5.9
2.0.6.0
29/04/2024
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.